Courseiva
Security Monitoring →hardMultiple Select

200-201 Security Monitoring Practice Question

A SOC analyst is tuning a SIEM correlation rule to detect port scanning. The rule should generate an alert when a single source IP connects to many different destination ports on multiple hosts within a short time. Which THREE conditions should be included in the rule?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Count of unique destination IPs > threshold

Option A is correct because a port scan is characterized by one source touching many distinct targets, so counting unique destination IPs above a threshold captures the horizontal spread across multiple hosts required by the rule. Option C is correct because the scenario specifies a single source IP, and grouping or filtering on that single source is what ties the many connections together as one scanning event rather than unrelated traffic. Option E is correct because counting unique destination ports above a threshold detects the vertical sweep of many ports, which is the defining signature of port scanning. Option B is not required because scans can target any port range, not just well-known ports, so restricting to well-known ports would miss scans of high or ephemeral ports. Option D is not appropriate because port scans typically involve small, often single-packet connections, so a high average packet count per connection would indicate data transfer or a different behavior, not scanning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Count of unique destination IPs > threshold

    Why this is correct

    Counting unique destination IPs above a threshold captures the horizontal spread of a scan, where one source probes many hosts. Combined with port and time-window conditions, it satisfies the stem's requirement to detect scanning across multiple hosts rather than a single target.

  • ✗

    Destination port is well-known

    Why it's wrong here

    Restricting to well-known ports narrows scanning detection to a small fixed range, missing scans that sweep ephemeral or high ports. It is tempting because common service ports are frequently targeted, but the rule must count many distinct destination ports regardless of their number.

  • ✓

    Single source IP

    Why this is correct

    Anchoring the rule on a single source IP isolates the scanner as the common origin, since a port scan originates from one host probing many targets. Without this constraint, the correlation would aggregate unrelated traffic from multiple sources, producing false positives and failing to identify the actual scanning actor.

  • ✗

    Average packet count per connection is high (e.g., >100)

    Why it's wrong here

    A high average packet count per connection describes data-heavy sessions, not scanning, which typically sends single small probes. It is tempting as an anomaly threshold, but the rule needs many distinct destination ports across multiple hosts from one source within a short window.

  • ✓

    Count of unique destination ports > threshold

    Why this is correct

    Counting unique destination ports above a threshold distinguishes scanning from legitimate repeated connections to one service. A high count of distinct ports touched by the same source within the window is the defining signature of port scanning, satisfying the rule's requirement to flag many-port probing activity.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.